Denial of Service Vulnerability in Ubuntu dpkg Tool

Denial of Service Vulnerability in Ubuntu dpkg Tool

First seen 7 May 2026, 21:08 UTC UbuntuLinuxsecurity 88% similarity 45.9

Article Content

Browse articles
ThreatCluster

A denial of service vulnerability has been identified in the dpkg tool of Ubuntu versions 25.10 and 24.04 LTS. Discovered by Yashashree Gund, the issue arises when dpkg-deb improperly handles specially crafted zstd-compressed .deb archives. If exploited, this flaw could cause dpkg-deb to stop responding, affecting both users and automated systems. The vulnerability is tracked as CVE-2026-2219 and was published on March 7, 2026. Users are advised to update to the latest package versions to mitigate the risk. The affected versions are dpkg 1.22.21ubuntu3.2 for Ubuntu 25.10 and dpkg 1.22.6ubuntu6.6 for Ubuntu 24.04 LTS. A standard system update will apply the necessary changes.

Key Points: • Denial of service vulnerability affects Ubuntu 25.10 and 24.04 LTS. • Exploitation could cause dpkg-deb to stop responding when handling crafted .deb files. • Users should update to specific dpkg versions to mitigate the risk.

ThreatCluster AI

Timeline

2026-03-07
CVE-2026-2219 published
A denial of service vulnerability in dpkg was disclosed, affecting Ubuntu 25.10 and 24.04 LTS.
Linuxsecurity
2026-05-07
Vulnerability announced
Ubuntu published an advisory regarding the dpkg vulnerability, urging users to update their systems.
Ubuntu

Community

Browse all →

Tracked Entities in This Story